Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-36159

Опубликовано: 26 сент. 2022
Источник: nvd
CVSS3: 8.8
EPSS Низкий

Описание

Contec FXA3200 version 1.13 and under were discovered to contain a hard coded hash password for root stored in the component /etc/shadow. As the password strength is weak, it can be cracked in few minutes. Through this credential, a malicious actor can access the Wireless LAN Manager interface and open the telnet port then sniff the traffic or inject any malware.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:contec:fxa3000_firmware:*:*:*:*:*:*:*:*
Версия до 1.13.00 (включая)
cpe:2.3:h:contec:fxa3000:-:*:*:*:*:*:*:*
Конфигурация 2

Одновременно

cpe:2.3:o:contec:fxa3020_firmware:*:*:*:*:*:*:*:*
Версия до 1.13.00 (включая)
cpe:2.3:h:contec:fxa3020:-:*:*:*:*:*:*:*
Конфигурация 3

Одновременно

cpe:2.3:o:contec:fxa3200_firmware:*:*:*:*:*:*:*:*
Версия до 1.13.00 (включая)
cpe:2.3:h:contec:fxa3200:-:*:*:*:*:*:*:*
Конфигурация 4

Одновременно

cpe:2.3:o:contec:fxa2000_firmware:*:*:*:*:*:*:*:*
Версия до 1.39.00 (исключая)
cpe:2.3:h:contec:fxa2000:-:*:*:*:*:*:*:*

EPSS

Процентиль: 51%
0.00281
Низкий

8.8 High

CVSS3

Дефекты

CWE-798
CWE-798

Связанные уязвимости

CVSS3: 8.8
github
больше 3 лет назад

Contec FXA3200 version 1.13 and under were discovered to contain a hard coded hash password for root stored in the component /etc/shadow. As the password strength is weak, it can be cracked in few minutes. Through this credential, a malicious actor can access the Wireless LAN Manager interface and open the telnet port then sniff the traffic or inject any malware.

EPSS

Процентиль: 51%
0.00281
Низкий

8.8 High

CVSS3

Дефекты

CWE-798
CWE-798